Showing posts with label S 2012. Show all posts
Showing posts with label S 2012. Show all posts

Wednesday, July 13, 2016

S 2012 Goes to Conference – Energy Authorization

It took a month and a half for the Senate to accomplish what everyone knew it would; yesterday the Senate rejected the House amendments to S 2012 and established a conference committee to deal with the differences between the two versions of the bill.

The cybersecurity provisions of the House and Senate versions should make it into the final bill. The most interesting thing to see will be which version of the ‘Critical electric infrastructure security’ {§1104 in the House passed version; §2001 in the Senate version} section of the bill will make it into the final bill. Likewise the House provision on the volatility of crude oil (§5009) should also make it into the final bill.

It is not clear how much work the Conference Committee will get done during the summer recess. For the most part the principals (the actual congresscritters) will be back in their districts raising money and glad handing the electorate. Some staff work will get done, but a conference is all about horse trading and deal making; that requires the active personal participation of the elected representatives.


If an appropriate compromise can be worked out that can allow the bill to be considered in the Senate, there is a chance that the bill could pass in the brief session between Labor Day and the election recess.

Thursday, May 26, 2016

House Amends and Passes S 2012 – Energy Policy

Last night the House passed an amended version of S 2012, the Energy Policy Modernization Act of 2016 by a nearly party-line vote of 241 – 178. Later the House voted to insist on its amendment and called for a conference committee.

Bill Provisions of Interest


The bill includes the following cybersecurity provisions from HR 8:

Sec. 1104. Critical electric infrastructure security.
Sec. 1106. Cyber Sense.
Sec. 2008. Report on smart meter security concerns.
Sec. 3126. Internet of Things report.

The bill includes the following chemical transportation safety provision from HR 8:

Sec. 5009. Study of volatility of crude oil.

Moving Forward


The Senate version of the bill passed by a vote of 85 – 12 with only Republicans voting No. The House version passed on a mainly partisan vote with 172 Democrats voting no. It will take the conference committee a while to work out a version of the bill that will be able to come to a vote in the Senate and still be acceptable to the leadership in the House. The bill that passed yesterday would not make it to the Senate floor.

A final version of the bill will probably include the provisions listed above; there is nothing there that is objectionable. The Senate bill had a slightly different version of §1104. It will be interesting to see how the differences are worked out.

The Senate bill has one additional cybersecurity provision that should also make it into the final bill:


Sec. 2002. Enhanced grid security.

Wednesday, April 20, 2016

Senate Resumes Considering S 2012

Yesterday the Senate resumed consideration of S 2012, the Energy Policy Modernization Act of 2015. There were 27 amendments considered en bloc and passed by unanimous consent. Four additional amendments (including the substitute language) were approved and four were rejected; all by voice votes. A unanimous consent agreement was reached to schedule a final vote on the bill for today.

Provisions of Interest


The language in the substitute amendment included two specific provisions that could be of specific interest to readers of this bill (described previously here):

• Critical Electric Infrastructure Information; and
• Enhanced Grid Security

Only six of the large number of amendments offered to this bill could have been of interest to readers of this blog. None of those were considered in yesterday’s actions. Those amendments were:

SA 2997 – Sen. WYDEN (D,OR) – Internet of Things;
SA 3163 – Sen. FISCHER (R,NE) – Pipes Act;
SA 3186 – Sen. FISCHER – OSHA Retail Facility Exemption;
SA 3196 – Sen. Mr. KIRK (R,IL) – Large Scale Cyber Incidents;
SA 3197 – Sen. COLLINS (R,ME) – Critical Electric Infrastructure at Greatest Risk;
SA 3236 – Sen. WYDEN – Energy Train Data Collection;

Moving Forward


It is being reported on Twitter that the bill passed this morning by a vote of 85 – 12; as expected a significant bipartisan majority. The question now is whether the House will take up this bill or whether the House will insist on the language in HR 8 that passed along a party-line vote and that the President has threatened to veto. The later choice would lead to a conference committee to work out the differences between the two bills.

NOTE: HR 636 passed yesterday, as expected, by a vote of 95 – 3.

Thursday, April 14, 2016

S 2012 Deal Reached

Yesterday a deal was reached in the Senate to allow for continued consideration of S 2012, the Energy Policy Modernization Act of 2015. It provides for an en bloc vote on 28 selected amendments with a 60 vote threshold to adopt the amendments. Four additional specific amendments will be considered individually, again with a 60 vote minimum for adoption.

None of the amendments that I described in a series of blog posts in January and February (here, here, here, and here) were among those covered in the agreement. The provisions in the base bill for the Critical Electric Infrastructure Information (CEII) program and the enhanced grid security provisions remain unchanged.


A date for these votes has not yet been set. Senators McConnell and Reed will work that out between them. I expect that it will be sometime next week. I would expect the en bloc amendments to pass with substantial bipartisan support. The remaining four amendments will be a much less sure thing for passage.

Monday, March 7, 2016

Congressional Hearings – Week of 3-6-16

Only the Senate is in session this week, the House is “working in their districts”. For most of the House members, this means that they are working on their re-election campaigns. The Senate is only holding one hearing this week that may be of interest to readers of this blog. It will be a Homeland Security and Government Affairs Committee hearing on the DHS budget on Tuesday. High-level conversation with the Secretary, don’t expect much in the way of details, but I would expect mentions of cybersecurity.

The Senate might get back to S 2012, the energy authorization bill, that has been held up over disagreements on including funding for programs to help the city of Flint, MI recover from its self-inflicted (or State inflicted, depending on how you look at it) drinking water contamination issues. There have been continuing behind the scenes negotiations on how to get passed this procedural impasse. We might see progress this week.

Monday, February 22, 2016

Committee Hearings – Week of 02-21-16

The House and Senate are back in Washington this week from their President’s Day recess. The spending issue season has started with three big budget hearings (for readers of this blog) this week. We also have a pipeline safety and cybersecurity hearings on the agenda.

FY 2017 Budget

The budget hearing process started in the Senate a couple of weeks ago and it gets into high gear in the House this week. Budget hearings are big picture looks at what government spending will look like in FY 2017 so don’t look for much in the way of details. The spending hearing will come later this spring.

The big three budget hearings this week are being held by House Appropriations Committee subcommittees. They are:


Department of Homeland Security Budget – Wednesday;
Department of Transportation Budget – Wednesday; and
Department of Defense Budget - Thursday

Pipeline Safety

The Subcommittee on Railroads, Pipelines, and Hazardous Materials of the House Transportation and Infrastructure Committee will be holding a hearing on Thursday on the “Reauthorization of DOT’s Pipeline Safety Program”. This is the start of the reauthorization process for FY 2017. The witness list includes:

• Marie Therese Dominguez, Administrator, PHMSA;
• Andrew Black, Association of Oil Pipe Lines (AOPL)
• Donald Santa, Interstate Natural Gas Association of America (INGAA)
• Cheryl Campbell, XCEL Energy; on behalf of the American Gas Association
• Carl Weimer, Pipeline Safety Trust

The Committee web site includes links to two interesting hearing documents; a staff briefing on the hearing issues and a staff review of the status of requirements from the 2011 Pipeline Safety Act.

Cybersecurity

The Subcommittee on Cybersecurity, Infrastructure Protection, and Security Technologies of the House Homeland Security Committee will be holding a hearing on Thursday on the "Emerging Cyber Threats to the United States". The witness list includes:

• Frank Cilluffo, Center for Cyber and Homeland Security;
• Jennifer Kolde, FireEye Threat Intelligence;
• Adam Bromwich, Security Technology and Response; and
• Isaac Porche, The RAND Corporation

On the Floor

There is one bill currently scheduled to come to the House floor this week that may be of specific interest to readers of this blog. On Tuesday HR 3584, the Transportation Security Administration Reform and Improvement Act of 2015, will be considered under suspension of the rules. This typically means that the Leadership expects that the bill will get broad bipartisan support. No amendments will be made under this provision.

The Senate does not provide a real schedule of what will be considered in the coming week, but there is an outside chance that an agreement to finish consideration of S 2012, the Energy Policy Modernization Act of 2015. Readers should remember that there was a lengthy amendment process (here, here and here) mostly completed on the bill, but it was being held-up over possible consideration of a variety of amendments on the Flint, MI water crisis.


Wednesday, February 3, 2016

Amendments to S 2012 – 02-02-16

Yesterday there were 47 amendments proposed for S 2012, the Energy Policy Modernization Act of 2015. Of those, three may be of specific interest to readers of this blog:

SA 3186. Mrs. FISCHER (R,NE), pg S493;
SA 3196. Mr. KIRK (R,IL), pg S501;
SA 3197. Ms. COLLINS (R,ME), pg S501;

OSHA Retail Facility Exemption

Fisher’s amendment would stop the Occupational Health and Safety Administration (OSHA) from changing the way it interprets which facilities are exempted from the Process Safety Management Standards (PSM) on the basis of being a ‘retail facility’. OSHA announced their narrowing of the interpretation of the term ‘retail facility’ last July. This amendment would stop any enforcement actions on the new definition until a rulemaking was completed establishing the new definition.

Large Scale Cyber Incidents

The Kirk amendment would establish ‘large scale cyber incident’ as an incident that could be covered under the disaster relief provisions of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 USC 5121 et seq). It specifically adds the words ‘cyber incident’ to the definition of ‘major disaster’ {§5122(2)}.

The amendment would add a new definition for the term “cyber incident” {new §5122(14)} which would be defined as:

“Actions taken against critical infrastructure through the use of computer networks that result in a significant adverse effect on the provision of essential services {as described in §5189e(a)(1)} which:
“Lasts for a period of more than 24-hours; and
“Affects the provision of essential services in more than 1 State.”

The term ‘essential services’ in the current law means any entity that is contributing to efforts to respond to an emergency or major disaster and provides {§5189e(a)}:

• Telecommunications service;
• Electrical power;
• Natural gas;
• Water and sewer services; or
• Any other essential service, as determined by the President.

Critical Electric Infrastructure at Greatest Risk

The Collins amendment would define ‘critical electric infrastructure’ as “a system or asset of the bulk-power system, whether physical or virtual, the incapacity or destruction of which would negatively affect national security, economic security, public health or safety, or any combination of those matters” {new §225(a)(2)}. It then goes on to define ‘covered entity’ as a critical infrastructure entity under EO 13636, §9(a).

The amendment then requires FERC and the DOE Secretary to:

“Identify and propose prioritized, risk-based actions to mitigate cyber risk for each covered entity such that, to the greatest extent practicable, a cyber security incident affecting that covered entity would be less likely to result in catastrophic regional or national effects on public health or safety, economic security, or national security, given current and projected cyber risks” {new §225(b)(2)}.

As to be expected reports to congress are required on the identified cyber security incidents and proposed mitigation measures.

Moving Forward

It is now looking like there will be a cloture vote on the substitute language on Thursday. This means that there will be a cut off for submission of new amendments to that language this afternoon.

The Fisher amendment is partisan in nature and neither she nor any of her co-sponsors are on the Energy and Natural Resources Committee. I would be surprised if this makes the short list of amendments that will make it to the floor. If it does get to the floor it will probably not get the 60 votes normally needed for passage during the amendment process.

The Kirk amendment is relatively non-partisan, but Kirk is not on the Energy and Natural Resources Committee. This is an iffy amendment for the purposes of making it to the floor for consideration, but if it does make it to the floor, it will probably get the 60 votes for passage.

The Collins amendment is relatively non-partisan and Sen. Collins is a senior and influential member of the Senate. This amendment has a good chance of getting considered and would almost certainly get the 60 votes necessary for adoption if it does make it to the floor.

Commentary

The two cybersecurity amendments introduced yesterday are very limited in scope. While the Kirk amendment does include cyber incidents in disaster relief coverage it only does so with respect to incidents that happen coincidentally to other disasters. The wording does not even allow the cyber incident to be caused by the coincidental disaster.


The Collins amendment would provide less restrictions on its coverage, but it provides very wide latitude in what FERC and DOE designate as a cyber risk and how it would be mitigated. There is no reason to expect that FERC will be any more aggressive with defining those risk and mitigation measures than they are now.

Tuesday, February 2, 2016

Amendments to S 2012 – 02-01-16

Yesterday there were 40 more amendments introduced for S 2012, the Energy Policy Modernization Act of 2015. Of those, one may be of specific interest to readers of this blog:

SA 3163, Mrs. FISCHER (R,NE), pg S431

This amendment is essential S 2276, the Pipes Act. This is not exactly the same version that was discussed in my earlier post. The Senate Commerce, Science and Transportation Committee marked-up that bill back in December and the revised version has not yet been published. The two new rulemakings and the TSA pipeline security report mentioned in that earlier blog are included in the language of this proposed amendment.

Since this amendment is energy related and it did receive bipartisan support in Committee, there is a pretty good chance that this might make it to the short list of amendments that will be considered on the Senate floor. If it does, it will almost certainly be approved

Thursday, January 28, 2016

Amendments to S 2012 – 01-27-16

Yesterday there were 84 amendments submitted to S 2012 that is currently being considered in the Senate. Of those only one may be of specific interest to readers of this blog:

SA 2997 – Sen. Wyden (D,OR) – pg S 272

Internet of Things

Wyden’s amendment would add paragraph (d), Internet of Things (IOT), to §1021, Study and report on energy savings benefits of operational efficiency programs and services. It would require that the report required under §1021 would include an analysis of the impact of IOT technology on energy and water systems. It would be required to identify IOT technology solutions that {new §1021(d)(B)(ii)}, “through features embedded in hardware and software from the outset” … “promote security, privacy, interoperability, and open standards”.

Moving Forward

Yesterday was only the first day of consideration of this complex bill. At this point in their deliberations there is no clear indication of how many or which amendments will ultimately be considered on the floor of the Senate. If this amendment does make it to the floor it will likely be approved since it only requires a modification to an existing report.

Commentary

This amendment contains an interesting definition of IOT. Paragraph (d)(1) defines IOT as a set of technologies that:

• Connect to the Internet; and
• Provide real-time and actionable analytics and predictive maintenance


The inclusion of a requirement for ‘actionable analytics and predictive maintenance’ a number of devices that most people would lump together under the IOT rubric. Even in the industrial IOT realm operational devices connected to control systems in electric utility or water utility facilities would not fall under this relatively limited definition.

Senate Considering S 2012

Yesterday the Senate began consideration of S 2012, the Energy Policy Modernization Act of 2015. Somehow I missed this bill when it was introduced back in September, but it is very similar to HR 8 that was passed by the House last month. The bill does contain cybersecurity related provisions, but certainly not all of those included in the House bill.

Critical Electric Infrastructure Information

Like the House bill, §2001 amends the Federal Power Act to include specific authority to designate Critical Electric Infrastructure Information (CEII). As I explained in an earlier post, while a CEII program does currently exist it is not specifically authorized by statute. This will become important when the National Archives and Records Administration finally publishes its final rule on Controlled Unclassified Information (CUI). Being authorized by statute would allow the DOE Secretary more latitude on the way CUI is controlled.

There are several provisions of the HR 8 CUI section that are not included in S 2012. They include provisions associated with:

• Submission of information to congress;
• Disclosure of protected information;
• Duration of designation;
• Removal of designation; and
• Judicial review of designations

The lack of coverage of these items in the bill simply means that the NARA regulations would govern these areas, not the DOE regulations.

Enhanced Grid Security

Section 2002 of the bill establishes a number of cybersecurity programs, some of which already exist in fact, if not in law. Each of the programs include authorized funding. They include:

• Cybersecurity sector specific agency designation;
• Cybersecurity for the energy sector research, development, and demonstration program;
• Energy sector component testing for cyberresilience program;
• Energy sector operational support for cyberresilience program;
• Modeling and assessing energy infrastructure risk;
• Study on expanding industry membership and participation in ES–ISAC

The component testing program is somewhat similar to the Cyber Sense program include in §1106 of HR 8. The Senate version is not nearly as comprehensive or detailed. The Senate program does include $15 Million in annual funding where the Cyber Sense program included no funding, relying entirely on 3rd party testing and certification.

Moving Forward

Consideration of the bill continues today and there is not currently a schedule for a final vote. Sen. Murkowski (R,AK) is working hard to keep the amendment process limited to energy matters so that the bill does not get saddled with any of the controversial riders that have earned HR 8 a Presidential veto threat.


It is very likely that this bill will pass in the Senate. The House will then have to decide whether or not to accept the Senate bill or insist on the language of HR 8. If the latter occurs there would probably be a conference committee formed to work out the differences in the two bills.
 
/* Use this with templates/template-twocol.html */